H. R. 2029—725
for any purpose other than to protect agency information
and agency information systems against cybersecurity risks
or to administer a contract or other agreement entered
into pursuant to subsection (c)(2) or as part of another
contract with the Secretary.
‘‘(2) LIMITATION ON LIABILITY.—No cause of action shall
lie in any court against a private entity for assistance provided
to the Secretary in accordance with this section and any contract or agreement entered into pursuant to subsection (c)(2).
‘‘(3) RULE OF CONSTRUCTION.—Nothing in paragraph (2)
shall be construed to authorize an Internet service provider
to break a user agreement with a customer without the consent
of the customer.
‘‘(f) PRIVACY OFFICER REVIEW.—Not later than 1 year after
the date of enactment of this section, the Privacy Officer appointed
under section 222, in consultation with the Attorney General, shall
review the policies and guidelines for the program carried out
under this section to ensure that the policies and guidelines are
consistent with applicable privacy laws, including those governing
the acquisition, interception, retention, use, and disclosure of
communications.’’.
(b) AGENCY RESPONSIBILITIES.—
(1) IN GENERAL.—Except as provided in paragraph (2)—
(A) not later than 1 year after the date of enactment
of this Act or 2 months after the date on which the Secretary makes available the intrusion detection and prevention capabilities under section 230(b)(1) of the Homeland
Security Act of 2002, as added by subsection (a), whichever
is later, the head of each agency shall apply and continue
to utilize the capabilities to all information traveling
between an agency information system and any information
system other than an agency information system; and
(B) not later than 6 months after the date on which
the Secretary makes available improvements to the intrusion detection and prevention capabilities pursuant to section 230(b)(2) of the Homeland Security Act of 2002, as
added by subsection (a), the head of each agency shall
apply and continue to utilize the improved intrusion detection and prevention capabilities.
(2) EXCEPTION.—The requirements under paragraph (1)
shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.
(3) DEFINITION.—Notwithstanding section 222, in this subsection, the term ‘‘agency information system’’ means an
information system owned or operated by an agency.
(4) RULE OF CONSTRUCTION.—Nothing in this subsection
shall be construed to limit an agency from applying the intrusion detection and prevention capabilities to an information
system other than an agency information system under section
230(b)(1) of the Homeland Security Act of 2002, as added by
subsection (a), at the discretion of the head of the agency
or as provided in relevant policies, directives, and guidelines.
(c) TABLE OF CONTENTS AMENDMENT.—The table of contents
in section 1(b) of the Homeland Security Act of 2002 (6 U.S.C.
101 note) is amended by striking the items relating to the first
section designated as section 226, the second section designated